
Critical #WooCommerce plugin privilege escalation (CVE-2026-1937)! The YayMail – WooCommerce Email Customizer plugin (≤ 4.3.2) has a missing capability check on the yaymail_import_state AJAX action, allowing authenticated users (Shop Manager+) to modify arbitrary options — including elevating privileges or creating admin users. 🔓 If you use this plugin on your e-commerce site, attackers could shift roles and take over your store without proper checks. 🛠 Mitigation: Update or remove the plugin now, and then run a full scan for malware/backdoors. Cleanup → https://quttera.com/remove-malware-from-website #WooCommerce #WordPress #CVE20261937 #WebSecurity #Infosec #ThreatIntel #CVE #Malware
Post summary
The post announces a privilege‑escalation flaw in the YayMail WooCommerce Email Customizer plugin (CVE‑2026‑1937) and urges users to update or remove the plugin, highlighting the missing capability check that enables attackers to create admin accounts.




